Plugin Vulnerability Hub
Plugin 34 known issues Latest disclosed Mar 23, 2026

WP Job Portal – AI-Powered Recruitment System for Company or Job Board website Vulnerabilities

Review known vulnerability records for the WordPress plugin WP Job Portal – AI-Powered Recruitment System for Company or Job Board website (`wp-job-portal`), including severity, CVE references, affected versions, and patch status.

Known Records
34
High or Critical
8
Linked CVEs
34
Last Updated
Mar 23, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for WP Job Portal – AI-Powered Recruitment System for Company or Job Board website so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
34 records include a published patch path.
Severity Mix
3 critical and 5 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for WP Job Portal – AI-Powered Recruitment System for Company or Job Board website

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-4306
WP Job Portal <= 2.4.8 - Unauthenticated SQL Injection via 'radius' Parameter

The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up to, and including, 2.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...

Published
Mar 23, 2026
Patched Release
2.4.9
Affected Versions
Versions up to 2.4.8
Next Step
Update to 2.4.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-24941
WP Job Portal <= 2.4.4 - Missing Authorization

The WP Job Portal – AI-Powered Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated att...

Published
Feb 03, 2026
Patched Release
2.4.5
Affected Versions
Versions up to 2.4.4
Next Step
Update to 2.4.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-24379
Job Portal <= 2.4.3 - Authenticated (Subscriber+) Insecure Direct Object Reference

The WP Job Portal – AI-Powered Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.3 due to missing validation on a user controlled key. This makes it possible for aut...

Published
Jan 24, 2026
Patched Release
2.4.4
Affected Versions
Versions up to 2.4.3
Next Step
Update to 2.4.4 or newer if supported.
Plugin Medium Patched: No CVE-2025-14467
WP Job Portal <= 2.4.4 - Authenticated (Editor+) Stored Cross-Site Scripting via Job Description Field

The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.4. This is due to the plugin explicitly whitelisting the `` tag in its `WPJOBPORTAL_ALLOWED_TAGS` configuration and using insufficient input sanitization...

Published
Dec 11, 2025
Patched Release
Not published
Affected Versions
Versions up to 2.3.9
Next Step
Open the full report for remediation notes and references.
Plugin Medium Patched: Yes CVE-2025-14293
WP Job Portal <= 2.4.0 - Authenticated (Subscriber+) Arbitrary File Read

The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 via the 'downloadCustomUploadedFile' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents...

Published
Dec 11, 2025
Patched Release
2.4.1
Affected Versions
Versions up to 2.4.0
Next Step
Update to 2.4.1 or newer if supported.
Plugin High Patched: Yes CVE-2025-48274
WP Job Portal <= 2.3.2 - Unauthenticated SQL Injection

The WP Job Portal plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac...

Published
Jun 11, 2025
Patched Release
2.3.3
Affected Versions
Versions up to 2.3.2
Next Step
Update to 2.3.3 or newer if supported.
Plugin High Patched: Yes CVE-2025-48273
WP Job Portal <= 2.3.2 - Unauthenticated Arbitrary File Download

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.3.2. This makes it possible for unauthenticated attackers to download and read the contents of arbitrary...

Published
May 24, 2025
Patched Release
2.3.3
Affected Versions
Versions up to 2.3.2
Next Step
Update to 2.3.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-48272
WP Job Portal <= 2.3.2 - Unauthenticated Insecure Direct Object Reference

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.2 due to missing validation on a user controlled key. This makes it possible for una...

Published
May 19, 2025
Patched Release
2.3.3
Affected Versions
Versions up to 2.3.2
Next Step
Update to 2.3.3 or newer if supported.
Plugin Critical Patched: Yes CVE-2025-47438
WP Job Portal <= 2.3.1 - Unauthenticated Local File Inclusion

The WP Job Portal plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files....

Published
May 08, 2025
Patched Release
2.3.2
Affected Versions
Versions up to 2.3.1
Next Step
Update to 2.3.2 or newer if supported.
Plugin High Patched: Yes CVE-2025-26935
WP Job Portal <= 2.2.8 - Authenticated (Contributor+) Local File Inclusion

The WP Job Portal plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.8. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the ex...

Published
Feb 23, 2025
Patched Release
2.2.9
Affected Versions
Versions up to 2.2.8
Next Step
Update to 2.2.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-13873
WP Job Portal <= 2.2.8 - Insecure Direct Object Reference to Authenticated (Subscriber+) User Photo Disconnection

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.8 via the deleteUserPhoto() function due to missing validation on a user controlled...

Published
Feb 21, 2025
Patched Release
2.2.9
Affected Versions
Versions up to 2.2.8
Next Step
Update to 2.2.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-13372
WP Job Portal <= 2.2.6 - Insecure Direct Object Reference to Unauthenticated Arbitrary Resume Download

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the getresumefiledownloadbyid() and getallresumefiles() functions due to missi...

Published
Jan 31, 2025
Patched Release
2.2.7
Affected Versions
Versions up to 2.2.6
Next Step
Update to 2.2.7 or newer if supported.